Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 69 of 292
CVE-2026-10884P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10884 [HIGH] CWE-416 CVE-2026-10884: Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who h
Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-10933P3HIGHCVSS 8.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10933 [HIGH] CWE-416 CVE-2026-10933: Use after free in Audio in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker
Use after free in Audio in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9893P3HIGHCVSS 8.3fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9893 [HIGH] CWE-416 CVE-2026-9893: Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had co
Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-8530P3HIGHCVSS 8.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8530 [HIGH] CWE-416 CVE-2026-8530: Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attac
Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14427P3HIGHCVSS 8.3fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14427 [HIGH] CWE-122 CVE-2026-14427: Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who h
Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-9993P3HIGHCVSS 8.3fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9993 [HIGH] CWE-416 CVE-2026-9993: Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had c
Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: High)
nvd
CVE-2024-2886P3HIGHCVSS 7.5fixed in 123.0.6312.86≥ 123.0.6312.86, < 123.0.6312.862024-03-26
CVE-2024-2886 [HIGH] CWE-416 CVE-2024-2886: Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to per
Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2010-0647P3CRITICALCVSS 9.3≤ 4.0.249.78v0.2.149.27+46 more2010-02-18
CVE-2010-0647 [CRITICAL] CWE-94 CVE-2010-0647: WebKit before r53525, as used in Google Chrome before 4.0.249.89, allows remote attackers to execute
WebKit before r53525, as used in Google Chrome before 4.0.249.89, allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed RUBY element, as demonstrated by a > sequence.
nvd
CVE-2010-3729P3CRITICALCVSS 9.8fixed in 6.0.472.622010-10-05
CVE-2010-3729 [CRITICAL] CWE-190 CVE-2010-3729: The SPDY protocol implementation in Google Chrome before 6.0.472.62 does not properly manage buffers
The SPDY protocol implementation in Google Chrome before 6.0.472.62 does not properly manage buffers, which might allow remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2026-17686P3HIGHCVSS 8.1≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17686 [HIGH] CWE-20 CVE-2026-17686: Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allo
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2011-1302P3CRITICALCVSS 9.3fixed in 10.0.648.2052011-04-15
CVE-2011-1302 [CRITICAL] CWE-787 CVE-2011-1302: Heap-based buffer overflow in the GPU process in Google Chrome before 10.0.648.205 allows remote att
Heap-based buffer overflow in the GPU process in Google Chrome before 10.0.648.205 allows remote attackers to execute arbitrary code via unknown vectors.
nvd
CVE-2026-11231P3HIGHCVSS 8.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11231 [HIGH] CWE-94 CVE-2026-11231: Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed
Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)
nvd
CVE-2021-21216P3MEDIUMCVSS 6.5fixed in 90.0.4430.72≥ unspecified, < 90.0.4430.722021-04-26
CVE-2021-21216 [MEDIUM] CWE-290 CVE-2021-21216: Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote att
Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2020-6522P3CRITICALCVSS 9.6fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6522 [CRITICAL] CVE-2020-6522: Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 al
Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2011-3961P3CRITICALCVSS 9.3fixed in 17.0.963.462012-02-09
CVE-2011-3961 [CRITICAL] CWE-362 CVE-2011-3961: Race condition in Google Chrome before 17.0.963.46 allows remote attackers to execute arbitrary code
Race condition in Google Chrome before 17.0.963.46 allows remote attackers to execute arbitrary code via vectors that trigger a crash of a utility process.
nvd
CVE-2020-6465P3CRITICALCVSS 9.6fixed in 83.0.4103.61≥ unspecified, < 83.0.4103.612020-05-21
CVE-2020-6465 [CRITICAL] CWE-416 CVE-2020-6465: Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote att
Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2013-2870P3CRITICALCVSS 9.3≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2870 [CRITICAL] CWE-399 CVE-2013-2870: Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote servers to execute a
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote servers to execute arbitrary code via crafted response traffic after a URL request.
nvd
CVE-2020-15961P3CRITICALCVSS 9.6fixed in 85.0.4183.121≥ unspecified, < 85.0.4183.1212020-09-21
CVE-2020-15961 [CRITICAL] CVE-2020-15961: Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an atta
Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2020-6462P3CRITICALCVSS 9.6fixed in 81.0.4044.129≥ unspecified, < 81.0.4044.1292020-05-21
CVE-2020-6462 [CRITICAL] CWE-416 CVE-2020-6462: Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker
Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2018-6090P3HIGHCVSS 8.8fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172018-12-04
CVE-2018-6090 [HIGH] CWE-190 CVE-2018-6090: An integer overflow that lead to a heap buffer-overflow in Skia in Google Chrome prior to 66.0.3359.
An integer overflow that lead to a heap buffer-overflow in Skia in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd